SlideShare a Scribd company logo
1 of 32
40
STKI’s Cyber
Governance initiative
Life is like riding a
bicycle.To keep
your balance, you
must keep
moving."
— Albert Einstein
STKI’s Cyber
Governance initiative
Page 1
STKI Company Confidential
41
41
It’s well known that so many
companies get hacked
Yet many executives believe it
will not affect them
Even the largest and most
prestigious ones
Page 2
STKI Company Confidential
42
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
4242
Cyber’s Problematic Reputation
“Cyber is holding us back from achieving all other initiatives”
Page 3
STKI Company Confidential
43
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
4343
Cyber governance initiative destination
Striking a balance between
the business needs and cyber,
risk & compliance needsCyber, governance & compliance are crucial for the survival of organizations
But they are also holding organizations back in many ways.
Executives don’t fully comprehend the importance of cyber security and their
personal responsibility.
Page 4
STKI Company Confidential
44
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
4444
Cyber Governance Initiative
Page 5
STKI Company Confidential
45
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
45
45
Demonstrate CEO
BOARD their cyber
responsibility
Determine business cyber
main principles
Allocate cyber budget,
head count & org.
structure
Trek name:
Zero trust security: Get top management on board
Page 6
STKI Company Confidential
46
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
4646
Source: STKI staffing report
Number of Employees/ Cyber personnel
Implement STKI’s market data &
best practices to receive
appropriate budgets and personnel!
Page 7
STKI Company Confidential
47
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
47
Build risk & cyber multi-
year program
Build cyber resilience
program
Trek name:
Design a Cyber Governance Plan
Design holistic cyber
measurement program
Use “Israel National Cyber
Directorate” guidance and tools
Page 8
STKI Company Confidential
48
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
4848
Israel National Cyber Directorate guidance
will boost cyber security in Israel!
Especially for non-regulated enterprises
Non-regulated CISO
I don’t have enough
budget and resources
I can’t explain this to the
CEOBoard
Page 9
STKI Company Confidential
49
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
49
49
Page 10
STKI Company Confidential
50
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
50
50
Organizations that want to participate in the betta program can contact tora@pmo.gov.il
Page 11
STKI Company Confidential
51
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
51
Don’t forget to secure the ENTIRE supply chain!
Page 12
STKI Company Confidential
52
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
52
STKI expects new regulation based on Israel National
Cyber Directorate guidance in several industries
Take a deep breath.We’ve only just started.
Page 13
STKI Company Confidential
53
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5353
Of boards are not trained to
deal with cyber security incidents!
Source: Einat Meyron cyber resilience consultant & The Cyber Security Source - 2017
Page 14
STKI Company Confidential
54
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5454
CEO  board member nightmare:
One Innocent phone call
Page 15
STKI Company Confidential
55
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5555
‫הגנה‬ ‫כלי‬ ‫איזה‬
‫מותקנים‬
‫אצלכם‬?
‫זה‬ ‫איך‬
‫קרה‬?
‫פיצוי‬ ‫יהיה‬
‫ללקוחות‬?
‫תוכלו‬ ‫שלא‬ ‫אומרים‬
‫ימים‬ ‫כמה‬ ‫לעבוד‬
‫יש‬‫תוכנית‬
‫חלופית‬?
‫הכנסתם‬
‫מו‬ ‫מנהל‬"‫מ‬
‫לתמונה‬?
‫אחריות‬
‫מי‬ ‫של‬?
‫לכם‬ ‫פרצו‬ ‫כבר‬
‫בעבר‬?
‫מייעץ‬ ‫מי‬
‫לכם‬?
‫זו‬ ‫אם‬ ‫ידוע‬
‫עבודה‬
‫פנימית‬?
‫את‬ ‫תפסיקו‬
‫המסחר‬
‫במניה‬?
‫רוצה‬ ‫אני‬
‫עם‬ ‫לדבר‬
‫המנכל‬
‫קיבלתם‬
‫איומים‬
‫מקדימים‬?
‫כמה‬
‫דורשים‬?
‫משפיע‬ ‫זה‬ ‫איך‬
‫הלקוחות‬ ‫על‬?
‫כי‬ ‫קרה‬ ‫זה‬
‫חסכתם‬
‫בעלויות‬?
‫כמה‬
‫מחשבים‬
‫נפגעו‬?
‫תעדכנו‬ ‫איך‬
‫אותנו‬?
‫היה‬ ‫איפה‬
‫הכשל‬?
‫המנכל‬ ‫אדוני‬,
‫תתפטר‬?
‫המלצות‬ ‫יישמתם‬
‫רגולטור‬?
‫לאחרונה‬ ‫מתי‬
‫את‬ ‫בדקתם‬
‫המערכות‬?
‫העובדים‬
‫שאין‬ ‫אומרים‬
‫מושג‬ ‫להם‬
‫קורה‬ ‫מה‬
‫תחזרו‬ ‫מתי‬
‫לפעילות‬?
‫איזה‬ ‫לכם‬ ‫ידוע‬
‫נדבקו‬ ‫מעגלים‬
‫בגללכם‬?
‫מידע‬ ‫נגנב‬
‫לקוחות‬ ‫של‬?
‫לא‬ ‫שלכם‬ ‫העובדים‬
‫לענות‬ ‫מה‬ ‫יודעים‬
‫ללקוחות‬
‫קשר‬ ‫יצרתם‬
‫עם‬‫ההאקר‬?
‫מוודאים‬ ‫הלקוחות‬ ‫איך‬
‫נפגעו‬ ‫שלא‬?
‫על‬ ‫משפיע‬ ‫זה‬ ‫איך‬
‫הדו‬"‫הרבעוני‬ ‫ח‬?
‫מיוחד‬ ‫משהו‬ ‫היה‬
‫בדרישה‬?
‫את‬ ‫כבר‬ ‫עדכנתם‬
‫להגנת‬ ‫הרשות‬
‫הסייבר‬?
‫צריכים‬ ‫לקוחות‬
‫תוכנה‬ ‫להתקין‬
‫אצלם‬ ‫חדשה‬?
‫ריגול‬ ‫זה‬
‫עסקי‬?
Source: Einat Meyron cyber resilience consultant
Page 16
STKI Company Confidential
56
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5656
‫המפתח‬ ‫היא‬ ‫שגרה‬ ‫בזמן‬ ‫החלטות‬ ‫קבלת‬
‫המשבר‬ ‫את‬ ‫שינהל‬ ‫הצוות‬ ‫מי‬‫מייד‬‫מדווח‬ ‫כשהוא‬?
‫מתקפה‬ ‫בזמן‬ ‫יעיל‬ ‫לתפקוד‬ ‫הקריטיות‬ ‫השאלות‬ ‫מהן‬?
‫נמוכה‬ ‫סיכון‬ ‫ברמת‬ ‫יסווג‬ ‫ומה‬ ‫דרמה‬ ‫נחשב‬ ‫מה‬?
‫ביטוח‬ ‫פוליסת‬ ‫יש‬ ‫האם‬?‫אומרת‬ ‫היא‬ ‫מה‬?
‫יותר‬ ‫נרחב‬ ‫משפטי‬ ‫יעוץ‬ ‫נדרש‬ ‫האם‬?
‫מוכרים‬ ‫הרלוונטי‬ ‫לרגולטור‬ ‫הדיווח‬ ‫נהלי‬ ‫האם‬?
‫ה‬ ‫עם‬ ‫קשר‬ ‫לביסוס‬ ‫מהלכים‬ ‫נעשו‬ ‫האם‬-CERT‫הלאומי‬?
‫הספקים‬ ‫עם‬ ‫הקשר‬ ‫מנוהל‬ ‫איך‬‫הלקוחות‬‫המניות‬ ‫בעלי‬?
‫הכופר‬ ‫תשלום‬ ‫לאפשרות‬ ‫מתייחס‬ ‫הארגון‬ ‫איך‬?
‫הכופר‬ ‫לתשלום‬ ‫הכסף‬ ‫מגיע‬ ‫מאיפה‬?
Source: Einat Meyron cyber resilience consultant
Page 17
STKI Company Confidential
57
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5757
Leverage the similarities between BCP & Cyber Resilience
BCP
(Business
Continuity Plan)
Cyber
Resilience
And make them work together in collaboration
Page 18
STKI Company Confidential
58
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5858
Trek name:
Adopt to changing regulations
Keep up with existing
regulations
Look as GDPR
becomes standard
Implement Privacy
Protection Regulation
Page 19
STKI Company Confidential
59
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
5959
GDPR Hype
GDPR is searched more
than Cyber Security
GDPR
Cyber Security
Page 20
STKI Company Confidential
60
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6060
Page 21
STKI Company Confidential
61
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6161
What does GDPR mean to our business? A lot!
The right to data portability allows individuals to obtain and reuse their
personal data for their own purposes across different services.
It allows them to move, copy or transfer personal data easily from one IT
environment to another in a safe and secure way, without hindrance to usability
Page 22
STKI Company Confidential
62
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
62
It will also change many processes and interaction methods.
Example first engagement with client and his consent to continue with the process:
Page 23
STKI Company Confidential
63
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6363
Consent Management
One of the new tools needed to maintain compliance
Page 24
STKI Company Confidential
64
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6464
Some organizations will have to appoint a DPO under
GDPR law
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/
The first point of contact for supervisory
authorities and for individuals whose data is
processed
Informs and advises the organization and its employees
about their obligations to comply with GDPR and other
data protection laws
Monitors compliance with GDPR and other data
protection laws, including managing internal data
protection activities
Advises on data protection impact assessments
Trains staff and conducts internal audits.
Page 25
STKI Company Confidential
65
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6565
source: konfidas
GDPR and Israeli privacy act are touching the same areas
Page 26
STKI Company Confidential
66
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6666
Eventually, it will come… So be prepared
Page 27
STKI Company Confidential
67
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6767
Trek name:
Cyber Security Operations
Enforce patches
Applying to new devices
(watches, pumps, cars, etc.)
Embrace new technologies and
prepare for new vulnerabilities
Re-adjust cyber security program
Embrace
DevSecOps
Automate Cyber
Operations and Use
AIML
Page 28
STKI Company Confidential
68
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6868
DevSecOps Manifesto:
Page 29
STKI Company Confidential
69
Copyright@STKI_2018 Do not remove source or attribution from any slide or graph
6969
DevSecOps tools - Embed SDLC (Secure Dev. life cycle) tools
into CICD:
• Static analysis tools
• Dynamic scanning (auto pen. tests)
• Embed operations data (logs, customer inputs) with security inputs
Page 30
STKI Company Confidential
70
70
70
Balance between business
needs and cyber, risk &
compliance needs
Page 31
STKI Company Confidential
71
71
71
Page 32
STKI Company Confidential

More Related Content

What's hot

Galit feins presentation v7 for summit
Galit feins presentation v7 for summitGalit feins presentation v7 for summit
Galit feins presentation v7 for summitGalit Fein
 
Le white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTLe white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTPaperjam_redaction
 
Innovate Right Now: Applied Innovation Exchange and Technovision
Innovate Right Now: Applied Innovation Exchange and TechnovisionInnovate Right Now: Applied Innovation Exchange and Technovision
Innovate Right Now: Applied Innovation Exchange and TechnovisionCapgemini
 
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...IDC Italy
 
Automation revolution AI ML RPAs 2019
Automation revolution   AI ML RPAs 2019Automation revolution   AI ML RPAs 2019
Automation revolution AI ML RPAs 2019Galit Fein
 
STKI Israeli IT Market Study 2020 vas volume 4 v3
STKI Israeli IT Market Study 2020 vas volume 4 v3STKI Israeli IT Market Study 2020 vas volume 4 v3
STKI Israeli IT Market Study 2020 vas volume 4 v3Dr. Jimmy Schwarzkopf
 
Galit Post-Covid ORGANIZATION Presentation
Galit Post-Covid ORGANIZATION Presentation Galit Post-Covid ORGANIZATION Presentation
Galit Post-Covid ORGANIZATION Presentation Galit Fein
 
STKI Israeli IT Market Study 2020 sftre volume 3 v3
STKI Israeli IT Market Study 2020 sftre volume 3 v3STKI Israeli IT Market Study 2020 sftre volume 3 v3
STKI Israeli IT Market Study 2020 sftre volume 3 v3Dr. Jimmy Schwarzkopf
 
Israel Cloud Computing
Israel  Cloud ComputingIsrael  Cloud Computing
Israel Cloud ComputingKatrinMelamed
 
Galit fein product positioning
Galit fein product positioningGalit fein product positioning
Galit fein product positioningGalit Fein
 
297727851 getting-to-the-cloud-event-2015
297727851 getting-to-the-cloud-event-2015297727851 getting-to-the-cloud-event-2015
297727851 getting-to-the-cloud-event-2015Inbalraanan
 
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane CherkaouiNouamane Cherkaoui
 
Next generation applications
Next generation applicationsNext generation applications
Next generation applicationsInbalraanan
 
Iot and cloud trends summit stki 2016
Iot and cloud trends summit stki 2016Iot and cloud trends summit stki 2016
Iot and cloud trends summit stki 2016Galit Fein
 

What's hot (19)

Galit feins presentation v7 for summit
Galit feins presentation v7 for summitGalit feins presentation v7 for summit
Galit feins presentation v7 for summit
 
CIO Strategies 2008
CIO Strategies 2008CIO Strategies 2008
CIO Strategies 2008
 
Le white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLTLe white paper de l'Ilnas sur la blockchain et les DLT
Le white paper de l'Ilnas sur la blockchain et les DLT
 
Innovate Right Now: Applied Innovation Exchange and Technovision
Innovate Right Now: Applied Innovation Exchange and TechnovisionInnovate Right Now: Applied Innovation Exchange and Technovision
Innovate Right Now: Applied Innovation Exchange and Technovision
 
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...
Data driven economy: l’impatto sulle infrastrutture IT e la data governance a...
 
Automation revolution AI ML RPAs 2019
Automation revolution   AI ML RPAs 2019Automation revolution   AI ML RPAs 2019
Automation revolution AI ML RPAs 2019
 
STKI Israeli IT Market Study 2020 vas volume 4 v3
STKI Israeli IT Market Study 2020 vas volume 4 v3STKI Israeli IT Market Study 2020 vas volume 4 v3
STKI Israeli IT Market Study 2020 vas volume 4 v3
 
Galit Post-Covid ORGANIZATION Presentation
Galit Post-Covid ORGANIZATION Presentation Galit Post-Covid ORGANIZATION Presentation
Galit Post-Covid ORGANIZATION Presentation
 
STKI Israeli IT Market Study 2020 sftre volume 3 v3
STKI Israeli IT Market Study 2020 sftre volume 3 v3STKI Israeli IT Market Study 2020 sftre volume 3 v3
STKI Israeli IT Market Study 2020 sftre volume 3 v3
 
Israel Cloud Computing
Israel  Cloud ComputingIsrael  Cloud Computing
Israel Cloud Computing
 
Galit fein product positioning
Galit fein product positioningGalit fein product positioning
Galit fein product positioning
 
297727851 getting-to-the-cloud-event-2015
297727851 getting-to-the-cloud-event-2015297727851 getting-to-the-cloud-event-2015
297727851 getting-to-the-cloud-event-2015
 
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
 
Next generation applications
Next generation applicationsNext generation applications
Next generation applications
 
Iot and cloud trends summit stki 2016
Iot and cloud trends summit stki 2016Iot and cloud trends summit stki 2016
Iot and cloud trends summit stki 2016
 
STKI Summit 1/2021 - REUT
STKI Summit 1/2021 - REUTSTKI Summit 1/2021 - REUT
STKI Summit 1/2021 - REUT
 
Pwc digital-iq-report final
Pwc digital-iq-report finalPwc digital-iq-report final
Pwc digital-iq-report final
 
Industry 4.0 UK Readiness Report
Industry 4.0 UK Readiness ReportIndustry 4.0 UK Readiness Report
Industry 4.0 UK Readiness Report
 
Fintech App Development Company
Fintech App Development CompanyFintech App Development Company
Fintech App Development Company
 

Similar to STKI Summit 2018 Cyber Governance Initiative

cisco-privacy-benchmark-study-2023.pdf
cisco-privacy-benchmark-study-2023.pdfcisco-privacy-benchmark-study-2023.pdf
cisco-privacy-benchmark-study-2023.pdfAproximacionAlFuturo
 
What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?PECB
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data DATAVERSITY
 
presentations for the STKI Summit 2022 part a 30_5_22.pdf
presentations for the STKI Summit 2022 part a 30_5_22.pdfpresentations for the STKI Summit 2022 part a 30_5_22.pdf
presentations for the STKI Summit 2022 part a 30_5_22.pdfDr. Jimmy Schwarzkopf
 
Results-Driven Trends in Today's Legal Operations
Results-Driven Trends in Today's Legal OperationsResults-Driven Trends in Today's Legal Operations
Results-Driven Trends in Today's Legal OperationsIFLP
 
Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021Cloudflare
 
Collaboration and The Human Factor - Reut 2022.pdf
Collaboration and The Human Factor - Reut 2022.pdfCollaboration and The Human Factor - Reut 2022.pdf
Collaboration and The Human Factor - Reut 2022.pdfDr. Jimmy Schwarzkopf
 
Cloud Security: A Business-Centric Approach in 12 Steps
Cloud Security: A Business-Centric Approach in 12 StepsCloud Security: A Business-Centric Approach in 12 Steps
Cloud Security: A Business-Centric Approach in 12 StepsOmar Khawaja
 
STKI Israeli IT market study 2022__2 pages
STKI Israeli IT market study 2022__2 pagesSTKI Israeli IT market study 2022__2 pages
STKI Israeli IT market study 2022__2 pagesDr. Jimmy Schwarzkopf
 
Is cyber security now too hard for enterprises?
Is cyber security now too hard for enterprises? Is cyber security now too hard for enterprises?
Is cyber security now too hard for enterprises? Pierre Audoin Consultants
 
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?OneTrust: Securing the Supply Chain: What Does Compliance Look Like?
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?Executive Leaders Network
 
STKI Summit 2022 presentation Jimmy
STKI Summit 2022  presentation Jimmy STKI Summit 2022  presentation Jimmy
STKI Summit 2022 presentation Jimmy Dr. Jimmy Schwarzkopf
 
Securing the Digital Future
Securing the Digital FutureSecuring the Digital Future
Securing the Digital FutureCognizant
 
Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014Felipe Lamus
 
Four mistakes to avoid when hiring your next security chief (print version ...
Four mistakes to avoid when hiring your next security chief (print version   ...Four mistakes to avoid when hiring your next security chief (print version   ...
Four mistakes to avoid when hiring your next security chief (print version ...Niren Thanky
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight:Banking and Open Source, 2018 CISO Report, GDPR LoomingOpen Source Insight:Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming Black Duck by Synopsys
 
Pci Europe 2009 Underside Of The Compliance Ecosystem
Pci Europe 2009   Underside Of The Compliance EcosystemPci Europe 2009   Underside Of The Compliance Ecosystem
Pci Europe 2009 Underside Of The Compliance Ecosystemkpatrickwheeler
 
The Internet of Things (IoT) and cybersecurity: A secure-by-design approach
The Internet of Things (IoT) and cybersecurity: A secure-by-design approachThe Internet of Things (IoT) and cybersecurity: A secure-by-design approach
The Internet of Things (IoT) and cybersecurity: A secure-by-design approachDeloitte United States
 

Similar to STKI Summit 2018 Cyber Governance Initiative (20)

cisco-privacy-benchmark-study-2023.pdf
cisco-privacy-benchmark-study-2023.pdfcisco-privacy-benchmark-study-2023.pdf
cisco-privacy-benchmark-study-2023.pdf
 
What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?What trends will 2018 bring for Business Continuity Professionals?
What trends will 2018 bring for Business Continuity Professionals?
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 
OCIO SUMMIT Galit Summit 2022
OCIO SUMMIT  Galit Summit 2022OCIO SUMMIT  Galit Summit 2022
OCIO SUMMIT Galit Summit 2022
 
presentations for the STKI Summit 2022 part a 30_5_22.pdf
presentations for the STKI Summit 2022 part a 30_5_22.pdfpresentations for the STKI Summit 2022 part a 30_5_22.pdf
presentations for the STKI Summit 2022 part a 30_5_22.pdf
 
Results-Driven Trends in Today's Legal Operations
Results-Driven Trends in Today's Legal OperationsResults-Driven Trends in Today's Legal Operations
Results-Driven Trends in Today's Legal Operations
 
Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021Why Zero Trust Architecture Will Become the New Normal in 2021
Why Zero Trust Architecture Will Become the New Normal in 2021
 
Collaboration and The Human Factor - Reut 2022.pdf
Collaboration and The Human Factor - Reut 2022.pdfCollaboration and The Human Factor - Reut 2022.pdf
Collaboration and The Human Factor - Reut 2022.pdf
 
Cloud Security: A Business-Centric Approach in 12 Steps
Cloud Security: A Business-Centric Approach in 12 StepsCloud Security: A Business-Centric Approach in 12 Steps
Cloud Security: A Business-Centric Approach in 12 Steps
 
STKI Israeli IT market study 2022__2 pages
STKI Israeli IT market study 2022__2 pagesSTKI Israeli IT market study 2022__2 pages
STKI Israeli IT market study 2022__2 pages
 
Is cyber security now too hard for enterprises?
Is cyber security now too hard for enterprises? Is cyber security now too hard for enterprises?
Is cyber security now too hard for enterprises?
 
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?OneTrust: Securing the Supply Chain: What Does Compliance Look Like?
OneTrust: Securing the Supply Chain: What Does Compliance Look Like?
 
STKI Summit 2022 presentation Jimmy
STKI Summit 2022  presentation Jimmy STKI Summit 2022  presentation Jimmy
STKI Summit 2022 presentation Jimmy
 
Securing the Digital Future
Securing the Digital FutureSecuring the Digital Future
Securing the Digital Future
 
Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014
 
Four mistakes to avoid when hiring your next security chief (print version ...
Four mistakes to avoid when hiring your next security chief (print version   ...Four mistakes to avoid when hiring your next security chief (print version   ...
Four mistakes to avoid when hiring your next security chief (print version ...
 
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight:Banking and Open Source, 2018 CISO Report, GDPR LoomingOpen Source Insight:Banking and Open Source, 2018 CISO Report, GDPR Looming
Open Source Insight: Banking and Open Source, 2018 CISO Report, GDPR Looming
 
Data Products and teams
Data Products and teamsData Products and teams
Data Products and teams
 
Pci Europe 2009 Underside Of The Compliance Ecosystem
Pci Europe 2009   Underside Of The Compliance EcosystemPci Europe 2009   Underside Of The Compliance Ecosystem
Pci Europe 2009 Underside Of The Compliance Ecosystem
 
The Internet of Things (IoT) and cybersecurity: A secure-by-design approach
The Internet of Things (IoT) and cybersecurity: A secure-by-design approachThe Internet of Things (IoT) and cybersecurity: A secure-by-design approach
The Internet of Things (IoT) and cybersecurity: A secure-by-design approach
 

More from Dr. Jimmy Schwarzkopf

STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdfDr. Jimmy Schwarzkopf
 
STKI Israeli Market Study 2023 version 2
STKI Israeli Market Study 2023 version 2 STKI Israeli Market Study 2023 version 2
STKI Israeli Market Study 2023 version 2 Dr. Jimmy Schwarzkopf
 
STKI Israeli IT market study 2022 version 2
STKI Israeli IT market study 2022 version 2 STKI Israeli IT market study 2022 version 2
STKI Israeli IT market study 2022 version 2 Dr. Jimmy Schwarzkopf
 
NEXT generation enterprise applications
NEXT generation enterprise applicationsNEXT generation enterprise applications
NEXT generation enterprise applicationsDr. Jimmy Schwarzkopf
 
Journey for a data driven organization
Journey for a data driven organizationJourney for a data driven organization
Journey for a data driven organizationDr. Jimmy Schwarzkopf
 
STKI Israeli it market study 2021 revised V2 2 2 slides per page
STKI Israeli it market study 2021 revised  V2  2    2 slides per page STKI Israeli it market study 2021 revised  V2  2    2 slides per page
STKI Israeli it market study 2021 revised V2 2 2 slides per page Dr. Jimmy Schwarzkopf
 
STKI Israeli it market study 2021 revised V2 2
STKI Israeli it market study 2021 revised  V2  2STKI Israeli it market study 2021 revised  V2  2
STKI Israeli it market study 2021 revised V2 2Dr. Jimmy Schwarzkopf
 
STKI Israeli it market study 2021 revised V2
STKI Israeli it market study 2021 revised  V2STKI Israeli it market study 2021 revised  V2
STKI Israeli it market study 2021 revised V2Dr. Jimmy Schwarzkopf
 
STKI annual Israeli IT market study 2021 (revised ) 2 pages version
STKI annual Israeli IT market study 2021  (revised )  2 pages versionSTKI annual Israeli IT market study 2021  (revised )  2 pages version
STKI annual Israeli IT market study 2021 (revised ) 2 pages versionDr. Jimmy Schwarzkopf
 
STKI Israeli IT Market Study 2020 intro volume 1v3
STKI Israeli IT Market Study  2020 intro volume 1v3STKI Israeli IT Market Study  2020 intro volume 1v3
STKI Israeli IT Market Study 2020 intro volume 1v3Dr. Jimmy Schwarzkopf
 
STKI Israeli IT Market Study 2020 hwre volume 2 v3
STKI Israeli IT Market Study  2020 hwre volume 2 v3STKI Israeli IT Market Study  2020 hwre volume 2 v3
STKI Israeli IT Market Study 2020 hwre volume 2 v3Dr. Jimmy Schwarzkopf
 
STKI IT Market Study 2019 version 2
STKI IT Market Study 2019 version 2 STKI IT Market Study 2019 version 2
STKI IT Market Study 2019 version 2 Dr. Jimmy Schwarzkopf
 
STKI Summit 2019 Innovation Terroir
STKI Summit 2019   Innovation Terroir STKI Summit 2019   Innovation Terroir
STKI Summit 2019 Innovation Terroir Dr. Jimmy Schwarzkopf
 

More from Dr. Jimmy Schwarzkopf (20)

STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf
 
STKI Israeli Market Study 2023 version 2
STKI Israeli Market Study 2023 version 2 STKI Israeli Market Study 2023 version 2
STKI Israeli Market Study 2023 version 2
 
STKI Israeli Market Study 2023
STKI Israeli Market Study 2023 STKI Israeli Market Study 2023
STKI Israeli Market Study 2023
 
CTO Summit 2022
CTO Summit 2022 CTO Summit 2022
CTO Summit 2022
 
Product management Summit 2022
Product management Summit 2022Product management Summit 2022
Product management Summit 2022
 
Discovery in product management
Discovery in product management Discovery in product management
Discovery in product management
 
STKI Israeli IT market study 2022 version 2
STKI Israeli IT market study 2022 version 2 STKI Israeli IT market study 2022 version 2
STKI Israeli IT market study 2022 version 2
 
STKI Israeli IT market study 2022
STKI Israeli IT market study 2022STKI Israeli IT market study 2022
STKI Israeli IT market study 2022
 
NEXT generation enterprise applications
NEXT generation enterprise applicationsNEXT generation enterprise applications
NEXT generation enterprise applications
 
Journey for a data driven organization
Journey for a data driven organizationJourney for a data driven organization
Journey for a data driven organization
 
CTO presentation
CTO presentation  CTO presentation
CTO presentation
 
Big iIT stagnation
Big iIT stagnationBig iIT stagnation
Big iIT stagnation
 
STKI Israeli it market study 2021 revised V2 2 2 slides per page
STKI Israeli it market study 2021 revised  V2  2    2 slides per page STKI Israeli it market study 2021 revised  V2  2    2 slides per page
STKI Israeli it market study 2021 revised V2 2 2 slides per page
 
STKI Israeli it market study 2021 revised V2 2
STKI Israeli it market study 2021 revised  V2  2STKI Israeli it market study 2021 revised  V2  2
STKI Israeli it market study 2021 revised V2 2
 
STKI Israeli it market study 2021 revised V2
STKI Israeli it market study 2021 revised  V2STKI Israeli it market study 2021 revised  V2
STKI Israeli it market study 2021 revised V2
 
STKI annual Israeli IT market study 2021 (revised ) 2 pages version
STKI annual Israeli IT market study 2021  (revised )  2 pages versionSTKI annual Israeli IT market study 2021  (revised )  2 pages version
STKI annual Israeli IT market study 2021 (revised ) 2 pages version
 
STKI Israeli IT Market Study 2020 intro volume 1v3
STKI Israeli IT Market Study  2020 intro volume 1v3STKI Israeli IT Market Study  2020 intro volume 1v3
STKI Israeli IT Market Study 2020 intro volume 1v3
 
STKI Israeli IT Market Study 2020 hwre volume 2 v3
STKI Israeli IT Market Study  2020 hwre volume 2 v3STKI Israeli IT Market Study  2020 hwre volume 2 v3
STKI Israeli IT Market Study 2020 hwre volume 2 v3
 
STKI IT Market Study 2019 version 2
STKI IT Market Study 2019 version 2 STKI IT Market Study 2019 version 2
STKI IT Market Study 2019 version 2
 
STKI Summit 2019 Innovation Terroir
STKI Summit 2019   Innovation Terroir STKI Summit 2019   Innovation Terroir
STKI Summit 2019 Innovation Terroir
 

Recently uploaded

Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfhans926745
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 

Recently uploaded (20)

Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 

STKI Summit 2018 Cyber Governance Initiative

  • 1. 40 STKI’s Cyber Governance initiative Life is like riding a bicycle.To keep your balance, you must keep moving." — Albert Einstein STKI’s Cyber Governance initiative Page 1 STKI Company Confidential
  • 2. 41 41 It’s well known that so many companies get hacked Yet many executives believe it will not affect them Even the largest and most prestigious ones Page 2 STKI Company Confidential
  • 3. 42 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 4242 Cyber’s Problematic Reputation “Cyber is holding us back from achieving all other initiatives” Page 3 STKI Company Confidential
  • 4. 43 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 4343 Cyber governance initiative destination Striking a balance between the business needs and cyber, risk & compliance needsCyber, governance & compliance are crucial for the survival of organizations But they are also holding organizations back in many ways. Executives don’t fully comprehend the importance of cyber security and their personal responsibility. Page 4 STKI Company Confidential
  • 5. 44 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 4444 Cyber Governance Initiative Page 5 STKI Company Confidential
  • 6. 45 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 45 45 Demonstrate CEO BOARD their cyber responsibility Determine business cyber main principles Allocate cyber budget, head count & org. structure Trek name: Zero trust security: Get top management on board Page 6 STKI Company Confidential
  • 7. 46 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 4646 Source: STKI staffing report Number of Employees/ Cyber personnel Implement STKI’s market data & best practices to receive appropriate budgets and personnel! Page 7 STKI Company Confidential
  • 8. 47 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 47 Build risk & cyber multi- year program Build cyber resilience program Trek name: Design a Cyber Governance Plan Design holistic cyber measurement program Use “Israel National Cyber Directorate” guidance and tools Page 8 STKI Company Confidential
  • 9. 48 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 4848 Israel National Cyber Directorate guidance will boost cyber security in Israel! Especially for non-regulated enterprises Non-regulated CISO I don’t have enough budget and resources I can’t explain this to the CEOBoard Page 9 STKI Company Confidential
  • 10. 49 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 49 49 Page 10 STKI Company Confidential
  • 11. 50 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 50 50 Organizations that want to participate in the betta program can contact tora@pmo.gov.il Page 11 STKI Company Confidential
  • 12. 51 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 51 Don’t forget to secure the ENTIRE supply chain! Page 12 STKI Company Confidential
  • 13. 52 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 52 STKI expects new regulation based on Israel National Cyber Directorate guidance in several industries Take a deep breath.We’ve only just started. Page 13 STKI Company Confidential
  • 14. 53 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5353 Of boards are not trained to deal with cyber security incidents! Source: Einat Meyron cyber resilience consultant & The Cyber Security Source - 2017 Page 14 STKI Company Confidential
  • 15. 54 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5454 CEO board member nightmare: One Innocent phone call Page 15 STKI Company Confidential
  • 16. 55 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5555 ‫הגנה‬ ‫כלי‬ ‫איזה‬ ‫מותקנים‬ ‫אצלכם‬? ‫זה‬ ‫איך‬ ‫קרה‬? ‫פיצוי‬ ‫יהיה‬ ‫ללקוחות‬? ‫תוכלו‬ ‫שלא‬ ‫אומרים‬ ‫ימים‬ ‫כמה‬ ‫לעבוד‬ ‫יש‬‫תוכנית‬ ‫חלופית‬? ‫הכנסתם‬ ‫מו‬ ‫מנהל‬"‫מ‬ ‫לתמונה‬? ‫אחריות‬ ‫מי‬ ‫של‬? ‫לכם‬ ‫פרצו‬ ‫כבר‬ ‫בעבר‬? ‫מייעץ‬ ‫מי‬ ‫לכם‬? ‫זו‬ ‫אם‬ ‫ידוע‬ ‫עבודה‬ ‫פנימית‬? ‫את‬ ‫תפסיקו‬ ‫המסחר‬ ‫במניה‬? ‫רוצה‬ ‫אני‬ ‫עם‬ ‫לדבר‬ ‫המנכל‬ ‫קיבלתם‬ ‫איומים‬ ‫מקדימים‬? ‫כמה‬ ‫דורשים‬? ‫משפיע‬ ‫זה‬ ‫איך‬ ‫הלקוחות‬ ‫על‬? ‫כי‬ ‫קרה‬ ‫זה‬ ‫חסכתם‬ ‫בעלויות‬? ‫כמה‬ ‫מחשבים‬ ‫נפגעו‬? ‫תעדכנו‬ ‫איך‬ ‫אותנו‬? ‫היה‬ ‫איפה‬ ‫הכשל‬? ‫המנכל‬ ‫אדוני‬, ‫תתפטר‬? ‫המלצות‬ ‫יישמתם‬ ‫רגולטור‬? ‫לאחרונה‬ ‫מתי‬ ‫את‬ ‫בדקתם‬ ‫המערכות‬? ‫העובדים‬ ‫שאין‬ ‫אומרים‬ ‫מושג‬ ‫להם‬ ‫קורה‬ ‫מה‬ ‫תחזרו‬ ‫מתי‬ ‫לפעילות‬? ‫איזה‬ ‫לכם‬ ‫ידוע‬ ‫נדבקו‬ ‫מעגלים‬ ‫בגללכם‬? ‫מידע‬ ‫נגנב‬ ‫לקוחות‬ ‫של‬? ‫לא‬ ‫שלכם‬ ‫העובדים‬ ‫לענות‬ ‫מה‬ ‫יודעים‬ ‫ללקוחות‬ ‫קשר‬ ‫יצרתם‬ ‫עם‬‫ההאקר‬? ‫מוודאים‬ ‫הלקוחות‬ ‫איך‬ ‫נפגעו‬ ‫שלא‬? ‫על‬ ‫משפיע‬ ‫זה‬ ‫איך‬ ‫הדו‬"‫הרבעוני‬ ‫ח‬? ‫מיוחד‬ ‫משהו‬ ‫היה‬ ‫בדרישה‬? ‫את‬ ‫כבר‬ ‫עדכנתם‬ ‫להגנת‬ ‫הרשות‬ ‫הסייבר‬? ‫צריכים‬ ‫לקוחות‬ ‫תוכנה‬ ‫להתקין‬ ‫אצלם‬ ‫חדשה‬? ‫ריגול‬ ‫זה‬ ‫עסקי‬? Source: Einat Meyron cyber resilience consultant Page 16 STKI Company Confidential
  • 17. 56 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5656 ‫המפתח‬ ‫היא‬ ‫שגרה‬ ‫בזמן‬ ‫החלטות‬ ‫קבלת‬ ‫המשבר‬ ‫את‬ ‫שינהל‬ ‫הצוות‬ ‫מי‬‫מייד‬‫מדווח‬ ‫כשהוא‬? ‫מתקפה‬ ‫בזמן‬ ‫יעיל‬ ‫לתפקוד‬ ‫הקריטיות‬ ‫השאלות‬ ‫מהן‬? ‫נמוכה‬ ‫סיכון‬ ‫ברמת‬ ‫יסווג‬ ‫ומה‬ ‫דרמה‬ ‫נחשב‬ ‫מה‬? ‫ביטוח‬ ‫פוליסת‬ ‫יש‬ ‫האם‬?‫אומרת‬ ‫היא‬ ‫מה‬? ‫יותר‬ ‫נרחב‬ ‫משפטי‬ ‫יעוץ‬ ‫נדרש‬ ‫האם‬? ‫מוכרים‬ ‫הרלוונטי‬ ‫לרגולטור‬ ‫הדיווח‬ ‫נהלי‬ ‫האם‬? ‫ה‬ ‫עם‬ ‫קשר‬ ‫לביסוס‬ ‫מהלכים‬ ‫נעשו‬ ‫האם‬-CERT‫הלאומי‬? ‫הספקים‬ ‫עם‬ ‫הקשר‬ ‫מנוהל‬ ‫איך‬‫הלקוחות‬‫המניות‬ ‫בעלי‬? ‫הכופר‬ ‫תשלום‬ ‫לאפשרות‬ ‫מתייחס‬ ‫הארגון‬ ‫איך‬? ‫הכופר‬ ‫לתשלום‬ ‫הכסף‬ ‫מגיע‬ ‫מאיפה‬? Source: Einat Meyron cyber resilience consultant Page 17 STKI Company Confidential
  • 18. 57 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5757 Leverage the similarities between BCP & Cyber Resilience BCP (Business Continuity Plan) Cyber Resilience And make them work together in collaboration Page 18 STKI Company Confidential
  • 19. 58 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5858 Trek name: Adopt to changing regulations Keep up with existing regulations Look as GDPR becomes standard Implement Privacy Protection Regulation Page 19 STKI Company Confidential
  • 20. 59 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 5959 GDPR Hype GDPR is searched more than Cyber Security GDPR Cyber Security Page 20 STKI Company Confidential
  • 21. 60 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6060 Page 21 STKI Company Confidential
  • 22. 61 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6161 What does GDPR mean to our business? A lot! The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability Page 22 STKI Company Confidential
  • 23. 62 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 62 It will also change many processes and interaction methods. Example first engagement with client and his consent to continue with the process: Page 23 STKI Company Confidential
  • 24. 63 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6363 Consent Management One of the new tools needed to maintain compliance Page 24 STKI Company Confidential
  • 25. 64 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6464 Some organizations will have to appoint a DPO under GDPR law https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/data-protection-officers/ The first point of contact for supervisory authorities and for individuals whose data is processed Informs and advises the organization and its employees about their obligations to comply with GDPR and other data protection laws Monitors compliance with GDPR and other data protection laws, including managing internal data protection activities Advises on data protection impact assessments Trains staff and conducts internal audits. Page 25 STKI Company Confidential
  • 26. 65 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6565 source: konfidas GDPR and Israeli privacy act are touching the same areas Page 26 STKI Company Confidential
  • 27. 66 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6666 Eventually, it will come… So be prepared Page 27 STKI Company Confidential
  • 28. 67 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6767 Trek name: Cyber Security Operations Enforce patches Applying to new devices (watches, pumps, cars, etc.) Embrace new technologies and prepare for new vulnerabilities Re-adjust cyber security program Embrace DevSecOps Automate Cyber Operations and Use AIML Page 28 STKI Company Confidential
  • 29. 68 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6868 DevSecOps Manifesto: Page 29 STKI Company Confidential
  • 30. 69 Copyright@STKI_2018 Do not remove source or attribution from any slide or graph 6969 DevSecOps tools - Embed SDLC (Secure Dev. life cycle) tools into CICD: • Static analysis tools • Dynamic scanning (auto pen. tests) • Embed operations data (logs, customer inputs) with security inputs Page 30 STKI Company Confidential
  • 31. 70 70 70 Balance between business needs and cyber, risk & compliance needs Page 31 STKI Company Confidential